CVE-2026-12957

Source
https://cve.org/CVERecord?id=CVE-2026-12957
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12957.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-12957
Aliases
  • GHSA-xhcr-j4j9-3gh7
Published
2026-06-23T16:02:53Z
Modified
2026-08-16T03:48:25Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Arbitrary Code Execution in Language Servers for AWS
Details

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.

To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-732"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12957.json"
}
References

Affected packages

Git / github.com/Amazon-Q-Developer/language-servers

Affected ranges

Type
GIT
Repo
https://github.com/Amazon-Q-Developer/language-servers
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.65.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

agentic-1.*
agentic-1.24.0
agentic-1.33.0
agentic-1.55.0
Other
agentic-pre-release-4-29-2026
chat-client/0.*
chat-client/0.0.4
chat-client/0.0.5
chat-client/v0.*
chat-client/v0.0.4
chat-client/v0.0.5
chat-client/v0.0.6
chat-client/v0.0.7
chat-client/v0.0.8
chat-client/v0.0.9
chat-client/v0.1.0
chat-client/v0.1.1
chat-client/v0.1.10
chat-client/v0.1.11
chat-client/v0.1.12
chat-client/v0.1.13
chat-client/v0.1.14
chat-client/v0.1.15
chat-client/v0.1.16
chat-client/v0.1.17
chat-client/v0.1.18
chat-client/v0.1.19
chat-client/v0.1.2
chat-client/v0.1.20
chat-client/v0.1.21
chat-client/v0.1.22
chat-client/v0.1.23
chat-client/v0.1.24
chat-client/v0.1.25
chat-client/v0.1.26
chat-client/v0.1.27
chat-client/v0.1.28
chat-client/v0.1.29
chat-client/v0.1.3
chat-client/v0.1.30
chat-client/v0.1.31
chat-client/v0.1.32
chat-client/v0.1.33
chat-client/v0.1.34
chat-client/v0.1.35
chat-client/v0.1.36
chat-client/v0.1.37
chat-client/v0.1.38
chat-client/v0.1.39
chat-client/v0.1.4
chat-client/v0.1.40
chat-client/v0.1.41
chat-client/v0.1.42
chat-client/v0.1.43
chat-client/v0.1.44
chat-client/v0.1.45
chat-client/v0.1.46
chat-client/v0.1.47
chat-client/v0.1.48
chat-client/v0.1.49
chat-client/v0.1.5
chat-client/v0.1.50
chat-client/v0.1.51
chat-client/v0.1.6
chat-client/v0.1.7
chat-client/v0.1.8
chat-client/v0.1.9
lsp-antlr4/v0.*
lsp-antlr4/v0.1.1
lsp-antlr4/v0.1.10
lsp-antlr4/v0.1.11
lsp-antlr4/v0.1.12
lsp-antlr4/v0.1.13
lsp-antlr4/v0.1.14
lsp-antlr4/v0.1.15
lsp-antlr4/v0.1.16
lsp-antlr4/v0.1.17
lsp-antlr4/v0.1.18
lsp-antlr4/v0.1.19
lsp-antlr4/v0.1.2
lsp-antlr4/v0.1.20
lsp-antlr4/v0.1.21
lsp-antlr4/v0.1.22
lsp-antlr4/v0.1.23
lsp-antlr4/v0.1.24
lsp-antlr4/v0.1.25
lsp-antlr4/v0.1.3
lsp-antlr4/v0.1.4
lsp-antlr4/v0.1.5
lsp-antlr4/v0.1.6
lsp-antlr4/v0.1.7
lsp-antlr4/v0.1.8
lsp-antlr4/v0.1.9
lsp-codewhisperer/v0.*
lsp-codewhisperer/v0.0.10
lsp-codewhisperer/v0.0.100
lsp-codewhisperer/v0.0.101
lsp-codewhisperer/v0.0.102
lsp-codewhisperer/v0.0.103
lsp-codewhisperer/v0.0.104
lsp-codewhisperer/v0.0.105
lsp-codewhisperer/v0.0.106
lsp-codewhisperer/v0.0.107
lsp-codewhisperer/v0.0.108
lsp-codewhisperer/v0.0.109
lsp-codewhisperer/v0.0.11
lsp-codewhisperer/v0.0.110
lsp-codewhisperer/v0.0.111
lsp-codewhisperer/v0.0.112
lsp-codewhisperer/v0.0.113
lsp-codewhisperer/v0.0.12
lsp-codewhisperer/v0.0.13
lsp-codewhisperer/v0.0.14
lsp-codewhisperer/v0.0.15
lsp-codewhisperer/v0.0.16
lsp-codewhisperer/v0.0.17
lsp-codewhisperer/v0.0.18
lsp-codewhisperer/v0.0.19
lsp-codewhisperer/v0.0.20
lsp-codewhisperer/v0.0.21
lsp-codewhisperer/v0.0.23
lsp-codewhisperer/v0.0.24
lsp-codewhisperer/v0.0.25
lsp-codewhisperer/v0.0.26
lsp-codewhisperer/v0.0.27
lsp-codewhisperer/v0.0.28
lsp-codewhisperer/v0.0.29
lsp-codewhisperer/v0.0.30
lsp-codewhisperer/v0.0.31
lsp-codewhisperer/v0.0.32
lsp-codewhisperer/v0.0.33
lsp-codewhisperer/v0.0.34
lsp-codewhisperer/v0.0.35
lsp-codewhisperer/v0.0.36
lsp-codewhisperer/v0.0.37
lsp-codewhisperer/v0.0.38
lsp-codewhisperer/v0.0.39
lsp-codewhisperer/v0.0.40
lsp-codewhisperer/v0.0.41
lsp-codewhisperer/v0.0.42
lsp-codewhisperer/v0.0.43
lsp-codewhisperer/v0.0.44
lsp-codewhisperer/v0.0.45
lsp-codewhisperer/v0.0.46
lsp-codewhisperer/v0.0.47
lsp-codewhisperer/v0.0.48
lsp-codewhisperer/v0.0.49
lsp-codewhisperer/v0.0.50
lsp-codewhisperer/v0.0.51
lsp-codewhisperer/v0.0.52
lsp-codewhisperer/v0.0.53
lsp-codewhisperer/v0.0.54
lsp-codewhisperer/v0.0.55
lsp-codewhisperer/v0.0.56
lsp-codewhisperer/v0.0.57
lsp-codewhisperer/v0.0.58
lsp-codewhisperer/v0.0.59
lsp-codewhisperer/v0.0.60
lsp-codewhisperer/v0.0.61
lsp-codewhisperer/v0.0.62
lsp-codewhisperer/v0.0.63
lsp-codewhisperer/v0.0.64
lsp-codewhisperer/v0.0.65
lsp-codewhisperer/v0.0.66
lsp-codewhisperer/v0.0.67
lsp-codewhisperer/v0.0.68
lsp-codewhisperer/v0.0.69
lsp-codewhisperer/v0.0.70
lsp-codewhisperer/v0.0.71
lsp-codewhisperer/v0.0.72
lsp-codewhisperer/v0.0.73
lsp-codewhisperer/v0.0.74
lsp-codewhisperer/v0.0.75
lsp-codewhisperer/v0.0.76
lsp-codewhisperer/v0.0.77
lsp-codewhisperer/v0.0.78
lsp-codewhisperer/v0.0.79
lsp-codewhisperer/v0.0.80
lsp-codewhisperer/v0.0.81
lsp-codewhisperer/v0.0.82
lsp-codewhisperer/v0.0.83
lsp-codewhisperer/v0.0.84
lsp-codewhisperer/v0.0.85
lsp-codewhisperer/v0.0.86
lsp-codewhisperer/v0.0.87
lsp-codewhisperer/v0.0.88
lsp-codewhisperer/v0.0.89
lsp-codewhisperer/v0.0.90
lsp-codewhisperer/v0.0.91
lsp-codewhisperer/v0.0.92
lsp-codewhisperer/v0.0.93
lsp-codewhisperer/v0.0.94
lsp-codewhisperer/v0.0.95
lsp-codewhisperer/v0.0.96
lsp-codewhisperer/v0.0.97
lsp-codewhisperer/v0.0.98
lsp-codewhisperer/v0.0.99
lsp-codewhisperer@0.*
lsp-codewhisperer@0.0.14
lsp-codewhisperer@0.0.3
lsp-codewhisperer@0.0.4
lsp-codewhisperer@0.0.5
lsp-codewhisperer@0.0.6
lsp-core/v0.*
lsp-core/v0.0.10
lsp-core/v0.0.11
lsp-core/v0.0.12
lsp-core/v0.0.13
lsp-core/v0.0.14
lsp-core/v0.0.15
lsp-core/v0.0.16
lsp-core/v0.0.17
lsp-core/v0.0.18
lsp-core/v0.0.19
lsp-core/v0.0.2
lsp-core/v0.0.20
lsp-core/v0.0.21
lsp-core/v0.0.3
lsp-core/v0.0.4
lsp-core/v0.0.5
lsp-core/v0.0.6
lsp-core/v0.0.7
lsp-core/v0.0.8
lsp-core/v0.0.9
lsp-json/v0.*
lsp-json/v0.1.0
lsp-json/v0.1.1
lsp-json/v0.1.10
lsp-json/v0.1.11
lsp-json/v0.1.12
lsp-json/v0.1.13
lsp-json/v0.1.14
lsp-json/v0.1.15
lsp-json/v0.1.16
lsp-json/v0.1.17
lsp-json/v0.1.18
lsp-json/v0.1.19
lsp-json/v0.1.2
lsp-json/v0.1.20
lsp-json/v0.1.21
lsp-json/v0.1.22
lsp-json/v0.1.23
lsp-json/v0.1.24
lsp-json/v0.1.25
lsp-json/v0.1.26
lsp-json/v0.1.3
lsp-json/v0.1.4
lsp-json/v0.1.5
lsp-json/v0.1.6
lsp-json/v0.1.7
lsp-json/v0.1.8
lsp-json/v0.1.9
lsp-json@0.*
lsp-json@0.0.1
lsp-partiql/v0.*
lsp-partiql/v0.0.10
lsp-partiql/v0.0.11
lsp-partiql/v0.0.12
lsp-partiql/v0.0.13
lsp-partiql/v0.0.14
lsp-partiql/v0.0.15
lsp-partiql/v0.0.16
lsp-partiql/v0.0.17
lsp-partiql/v0.0.18
lsp-partiql/v0.0.19
lsp-partiql/v0.0.20
lsp-partiql/v0.0.21
lsp-partiql/v0.0.22
lsp-partiql/v0.0.23
lsp-partiql/v0.0.3
lsp-partiql/v0.0.4
lsp-partiql/v0.0.5
lsp-partiql/v0.0.6
lsp-partiql/v0.0.7
lsp-partiql/v0.0.8
lsp-partiql/v0.0.9
lsp-partiql@0.*
lsp-partiql@0.0.1
lsp-partiql@0.0.2
lsp-yaml/v0.*
lsp-yaml/v0.1.0
lsp-yaml/v0.1.1
lsp-yaml/v0.1.10
lsp-yaml/v0.1.11
lsp-yaml/v0.1.12
lsp-yaml/v0.1.13
lsp-yaml/v0.1.14
lsp-yaml/v0.1.15
lsp-yaml/v0.1.16
lsp-yaml/v0.1.17
lsp-yaml/v0.1.18
lsp-yaml/v0.1.19
lsp-yaml/v0.1.2
lsp-yaml/v0.1.20
lsp-yaml/v0.1.21
lsp-yaml/v0.1.22
lsp-yaml/v0.1.23
lsp-yaml/v0.1.24
lsp-yaml/v0.1.25
lsp-yaml/v0.1.26
lsp-yaml/v0.1.3
lsp-yaml/v0.1.4
lsp-yaml/v0.1.5
lsp-yaml/v0.1.6
lsp-yaml/v0.1.7
lsp-yaml/v0.1.8
lsp-yaml/v0.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12957.json"